plugin

Document Library Lite Vulnerabilities

6 known security issues reported for the Document Library Lite WordPress plugin. Most recent disclosed Dec 16, 2025.

3 medium

Running Document Library Lite on your site? Check whether your installed version is affected.

Scan your site free

Document Library Lite [document-library-lite] <= 1.1.7 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows DOM-Based XSS.This issue affects Document Library Lite: from n/a through <= 1.1.7.

Affected:
up to 1.1.7
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-67986 on NVD →

Document Library Lite [document-library-lite] <= 1.1.7 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Document Library Lite: from n/a through <= 1.1.7.

Affected:
up to 1.1.7
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-67985 on NVD →

Document Library Lite <= 1.1.7 - Unauthenticated Insecure Direct Object Reference

medium

The Document Library Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 1.1.7
Fixed in:
1.2.0
Disclosed:
Dec 15, 2025

CVE-2025-67985 on NVD →

Document Library Lite <= 1.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Document Library Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts i...

CVSS:
4.4
Affected:
up to 1.1.7
Fixed in:
1.2.0
Disclosed:
Dec 15, 2025

CVE-2025-67986 on NVD →

Document Library Lite [document-library-lite] < 1.1.7

unknown

[en] The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler...

Affected:
up to 1.1.7
Fixed in:
1.1.7
Disclosed:
Nov 1, 2025

CVE-2025-11174 on NVD →

Document Library Lite <= 1.1.6 - Missing Authorization to Sensitive Information Exposure

medium

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler acce...

CVSS:
5.3
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Oct 31, 2025

CVE-2025-11174 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database